Atlassian released security updates to address a critical vulnerability affecting all versions of eight of its self-hosted products. The vulnerability is tracked as CVE-2026-21589 and has a CVSS score of 9.3, while it has been classified as a flaw that enables arbitrary file access.
The vulnerability can be exploited without authentication to access specific files within the web application's root path. Atlassian explains that exploitation requires precise knowledge of the target file's name and path, and does not allow attackers to browse or enumerate directory contents. However, some configurations may include sensitive files that increase the impact of a compromise.
Affected Products and Fixed Versions
The affected products include Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, Crucible, Confluence Data Center, Fisheye, Jira Service Management Data Center, and Jira Software Data Center.
Versions that include the fixes are Bitbucket 9.4.26, 10.2.8, and 10.5.1; Bamboo 10.2.24 and 12.1.12; Confluence 9.2.26 and 10.2.19; Crowd 6.3.7, 7.0.3, 7.1.7, and 7.2.4; as well as Crucible and Fisheye version 4.9.15. The company also fixed the flaw in Jira Service Management versions 5.12.40, 10.3.26, and 11.3.12, and in Jira versions 9.12.40, 10.3.26, and 11.3.12.
What Should Organizations Do?
Atlassian recommends that organizations update self-hosted deployments as soon as possible, or disconnect instances from the internet until the fixes are installed. The company's advisory also calls for restricting external access even for instances that use user authentication, and provides temporary mitigations for cases in which immediate updating is not possible.
Why Does This Matter?
The vulnerability's severity lies in the combination of two factors: no authentication is required, and it affects a broad range of collaboration, project management, and software development tools. According to WatchTowr, similar types of vulnerabilities have previously been exploited by ransomware groups and advanced persistent threat actors, and eight security vulnerabilities in Atlassian products are currently included in CISA's Known Exploited Vulnerabilities catalog.
WatchTowr specifically warns organizations that use single sign-on through Crowd; authentication data may be stored in plaintext and in a predictable path, potentially allowing it to be extracted and administrative users to be created when remote access to Crowd endpoints is possible. The company's threat intelligence expert, Yordan Ganchev, suggests applying the fix immediately or following Atlassian's guidance for deploying WAF rules to block exploitation attempts.
According to Atlassian and WatchTowr, there is no evidence that CVE-2026-21589 has been exploited in real-world attacks as of the publication date. However, this does not eliminate the priority of remediation, particularly because the source does not identify which files may be sensitive in each environment and does not establish that all configurations are exposed to the same degree.